Description
Tnega is a JavaScript backdoor associated with state sponsored actors that provides remote access capabilities on infected systems. It arrives through staged delivery chains, and its script based design lets operators update it quickly and evade signature based defenses. Detections under this name indicate targeted activity and warrant escalation beyond routine malware handling.
Stats
- First seen
- January 2022
- Last seen
- October 2026
Alert name variants
| Alert Name |
|---|
| ByteCode-JAVA.Trojan.Tnega |
| ByteCode-MSIL.Downloader.Tnega |
| ByteCode-MSIL.Trojan.Tnega |
| Document-HTML.Downloader.Tnega |
| Document-HTML.Dropper.Tnega |
| Document-HTML.Trojan.Tnega |
| Document-PDF.Trojan.Tnega |
| Document-XML.Trojan.Tnega |
| Email-MSG.Trojan.Tnega |
| MacOS.Trojan.Tnega |